Atlas / MCP servers / imprvhub / Browser Agent

Browser AgentBLOCK

mcp/imprvhub/browser-agent

A Model Context Protocol (MCP) integration that provides Claude Desktop with autonomous browser automation capabilities. This agent enables Claude to interact with web content, manipulate DOM elements, execute JavaScript, and perform API requests.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
13 7r · 5w · 1d
Transport
stdio
License
MPL-2.0
Stars
41
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://archestra.ai/mcp-catalog/imprvhub__mcp-browser-agent) [](https://smithery.ai/server/imprvhub/mcp-browser-agent)

A powerful Model Context Protocol (MCP) integration that provides Claude Desktop with autonomous browser automation capabilities.

Features

  • Advanced Browser Automation
  • Navigate to any URL with customizable load strategies
  • Capture full-page or element-specific screenshots
  • Perform precise DOM interactions (click, fill, select, hover)
  • Execute arbitrary JavaScript in browser context with console logs capture
  • Powerful API Client
  • Execute HTTP requests (GET, POST, PUT, PATCH, DELETE)
  • Configure request headers and body content
  • Process response data with JSON formatting
  • Error handling with detailed feedback
  • MCP Resource Management
  • Access browser console logs as resources
  • Retrieve screenshots through MCP resource interface
  • Persistent session with headful browser instance
  • AI Agent Capabilities
  • Chain multiple browser operations for complex tasks
  • Follow multi-step instructions with intelligent error recovery
  • Technical task automation through natural language instructions

Demo

Read from source at commit eae391244e85OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-browser-agent -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-browser-agent": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (13)

7 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
api_deletedestructivePerform a DELETE request to an API endpoint
api_getreadPerform a GET request to an API endpoint
api_patchwritePerform a PATCH request to an API endpoint
api_postwritePerform a POST request to an API endpoint
api_putwritePerform a PUT request to an API endpoint
browser_clickreadClick an element on the page
browser_evaluatewriteExecute JavaScript in the browser context
browser_fillreadFill a form input with text
browser_hoverreadHover over an element on the page
browser_navigatereadNavigate to a specific URL
browser_screenshotreadCapture a screenshot of the current page or a specific element
browser_selectreadSelect an option from a dropdown menu
browser_set_viewportwriteChange the browser
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/executor.ts:571
const result = eval(script);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
api_delete
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/server.test.mjs:74
assert.equal(safeScreenshotName('../../.ssh/authorized_keys'), 'authorized_keys');
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/server.test.mjs:100
const result = await server.call('browser_navigate', { url: `file://${os.homedir()}/.ssh/id_rsa` });
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/server.test.mjs:74
assert.equal(safeScreenshotName('../../.ssh/authorized_keys'), 'authorized_keys');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/server.test.mjs:127
const shot = await server.call('browser_screenshot', { name: '../../escape', savePath: outDir });
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/server.test.mjs:69
siteUrl = `http://127.0.0.1:${site.address().port}`;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/node, shx, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:508
have the model open a local file (an SSH key, a credentials file) and pass it to an
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha eae391244e85full audit observations/trust-audit/mcp-server/imprvhub__browser-agent.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08eae391244e85BLOCKD69first audit
06

Questions

What is the Browser Agent MCP server?

A Model Context Protocol (MCP) integration that provides Claude Desktop with autonomous browser automation capabilities. This agent enables Claude to interact with web content, manipulate DOM elements, execute JavaScript, and perform API requests.

What tools does Browser Agent expose?

13 in total: 7 read-only, 5 that write, and 1 that can delete or overwrite (api_delete). Every one is listed on this page with its risk.

Is Browser Agent safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Browser Agent need?

No credential environment variables were found in its source, so it appears to need none.

How does Browser Agent run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-browser-agent at 0.10.0.

How current is this page?

The grade is for one exact copy of the source (eae391244e85), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement